Malicious RTF / .DOC — malware analysis report

Static analysis result for SHA-256 d5875fb3d39a9ec2…

MALICIOUS

RTF / .DOC

203.5 KB First seen: 2021-10-26
MD5: c5f1c52134fc41ecb171c89602e937a4 SHA-1: 18567677d3724c4115fb27d16e0589e5982fc173 SHA-256: d5875fb3d39a9ec2781084bf80ad62c21371f6aa38d6f55919572f6a37ed6568
133 Risk Score

Malware Insights

MITRE ATT&CK
T1566.001 Spearphishing Attachment T1204.002 Malicious File T1059.003 Windows Command Shell

The RTF document contains embedded OLE object data and specifically triggers the Equation Editor CLSID, indicating an attempt to exploit a known vulnerability. The \objupdate directive further suggests that the embedded object is designed to be activated automatically upon opening, likely leading to the execution of a malicious payload.

Heuristics 3

  • Equation Editor CLSID critical RTF_EQUATION_EDITOR
    Equation Editor OLE CLSID found inside an OLE object — exploited by CVE-2017-11882 / CVE-2018-0802 / CVE-2018-0798
  • \objupdate forces OLE activation high RTF_OBJUPDATE
    RTF contains \objupdate — forces automatic OLE object instantiation when the document is opened, bypassing user interaction. Almost exclusively seen in Equation Editor exploit documents.
  • OLE object data medium RTF_OBJDATA
    RTF contains 2 \objdata section(s) — embedded OLE objects

Extracted artifacts 1

Files carved from inside the sample during analysis.

FilenameKindSourceSize
objdata_00_off00001045.bin
85b5115fe917ec9d5afbefb8d45da8e9b4a20f242e6b17d887567fe7a291dfac
rtf-objdata-decoded RTF \objdata at offset 0x1045 3653 bytes